Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] [VULN] Latest version 10.x (chrome 92.0) vulnerable to CVE-2021-30551 which was fixed on 91.0.4472.101 #261

Closed
0xSombra opened this issue Feb 24, 2022 · 1 comment
Labels
bug Something isn't working

Comments

@0xSombra
Copy link

Latest version 10.* using chromium 884014 is still vulnerable to CVE-2021-30551 which was patched on 91.0.4472.101

Looking at chromium at this commit, we find this DEPS at commit 622fd file
Which means it's using V8 at commit b0bf136 Version 9.2.227
The CVE fix was committed on commit f9857fd Version 9.3.0+ (?)

Please recompile chromium with the updated v8

@0xSombra 0xSombra added the bug Something isn't working label Feb 24, 2022
@0xSombra
Copy link
Author

Just realized it's puppeteer's fault for using r884014. oops!
I guess this is a duplicate of #254
I see there are problems with v11, v12 and v13. Updating to v10.4.0 should be enough to fix this issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant